ZXR10 5250 Series Command Reference
Parameter
Description
fragment
This rule is only valid for the message with the specified DSCP
value. Ignore this rule for other messages. The range of DSCP
value is 0 to 63.
cos
<
0-7
>
This rule is only valid for the cos-specified message. Ignore this
rule for other messages. The range of cos is 0 to 7.
<
vlan-id
>
This rule is only valid for messages with the specified VLAN ID.
Ignore this rule for other messages. The rule of VLAN ID is 1
to 4094.
<
vlan-mask
>
Optional VLAN mask. The default value is 0xfff.
<
source-mac
>
Source MAC address of the transmitted packet.
<
smac-mask
>
Source MAC mask.
any
(fourth)
The any keyword is used as the abbreviation of source MAC
address 00.00.00.00.00.00 and mask 00.00.00.00.00.00.
<
dest-mac
>
Destination MAC address of the transmitted packet.
<
dmac-mask
>
Destination MAC mask.
any
(fifth)
The any keyword is used as the abbreviation of destination MAC
address 00.00.00.00.00.00 and mask 00.00.00.00.00.00.
Guidelines
The TCP rule can match source-specified IPs, any source IPs, TCP source port numbers,
destination-specified IPs, any destination IPs, TCP destination port numbers, DSCP fields,
IP fragment fields, cos fields, VLAN fields, source-specified MACs, any source MACs,
destination-specified MACs, and any destination MACs. The rule can be bound to one or
all ports.
4.13.42 ingress-acl global rule type-udp
Purpose
This command sets the rule that the global ingress ACL matches the IPv4-UDP packet.
Command Mode
Global ingress ACL configuration mode
Syntax
rule
<
1-500
>{
permit
|
deny
}
port
{<
1-28
>|
any
}
udp
{<
source-ipaddr
><
sip-mask
>|
any
}[
source-port
<
0-65535
><
sport-mask
>]{<
destination-ipaddr
><
dip-mask
>|
any
}[
dest-port
<
0-65535
><
dport-mask
>][
dscp
<
0-63
>][
fragment
][
cos
<
0-7
>][<
vlan-id
>[<
vlan-mask
>]][<
sour
ce-mac
><
smac-mask
>|
any
][<
dest-mac
><
dmac-mask
>|
any
]
4-254
SJ-20131111172707-003|2013-11-27 (R1.0)
ZTE Proprietary and Confidential